In this research, the Blockchain-Based Data Protection and Privacy-Preserving (BDPPP) framework for IoT healthcare applications was designed and established to improve the data security and privacy of IoT healthcare applications by adopting blockchain and other cryptographic techniques. The study adopted a descriptive-analytical approach that involved a harmonious synthesis of several research papers to establish important security threats in IoT systems, emphasizing healthcare infrastructure. Both interviews and case studies were conducted with healthcare professionals and IT specialists to examine data privacy issues and weaknesses of IoT devices. The BDPPP framework was developed exploiting blockchain technology framework and cryptographic approaches including homomorphism encryption and zero-knowledge proofs to protect the information of the patient. Both smart contracts and edge computing were also applied to manage access to data as well as enhance real-time computation. The performance of the healthcare IoT network was assessed through a range of statistical parameters including latency, throughout, as well as encryption overhead were tested in a simulated IoT network environment. The findings showed that the proposed BDPPP framework provided maximum data confidentiality (encryption) at 100 percent and achieved high privacy standards (95% privacy performance) over IoT devices and also proved scalability up to 5000 IoT devices. Statistical tests used included; Logistic regression results showed that demographic characteristics including age and health conditions were not predictors of consent status. This means that the framework implemented in this study also achieved a low latency of 120 ms and a high through-put of 200 TPS despite the added layer of encryption. Overall, the proposed BDPPP framework is an innovative decentralized approach for further improvement of the IoT HC and data protection and privacy.
R P Tejushree, A.V.S.S. Prasad, C R Vedashree, Vishaka Rani Chandramule · 6 authors
Technology advancements have prompted researchers to investigate electronic voting, or "e-voting," to update and simplify the electoral process. In this research, we present a novel solution to these problems by fusing deep learning methods specifically, facial detection with blockchain technology to create an electronic voting system. To further enhance the security and integrity of the voting process, we apply deep learning techniques for facial detection. The voter's identification is then confirmed by deep learning models analyzing this data, which stops fraudulent voting and guarantees that only qualified people take part in the election process. Furthermore, our approach places a high priority on protecting voter privacy by utilizing methods like homomorphic encryption and zero-knowledge proofs, which enable vote counting without jeopardizing the voter's identity. Because blockchain technology is transparent, audits and verification are made easier, allowing interested parties to confirm the fairness of the electoral process. Our suggested electronic voting system provides a strong solution that tackles the primary issues of security, integrity, and privacy by merging deep learning combined with blockchain technologies for facial recognition.
Aman Luthra, James Cavanaugh, Hugo Renzzo Olcese, Michael W. Raymond · 7 authors
Auditing the trading history of an investment fund is an effective guard against financial frauds. But how can it be performed publicly, in real time, and without disclosing any commercial secret of a fund? In 2020, Luthra et al. developed ZeroAUDIT, a customized zero-knowledge protocol based on Merkle tree, which can assert that the accrued profit of an investment fund is as claimed given commitment/encryption of its transaction records. It was believed that a customized protocol has much better performance than general purpose zk-proof systems. In this work, we show that it is not true. We present ZeroAUDITGEN, a polymorphic zk-proof system for the same zk-audit problem, over a variety of general purpose zk-proof systems. We show that the prover and verifier cost can be greatly reduced by appropriate choice of security assumptions and design of concrete cryptographic constructions.
Intrusion Detection Systems (IDS) are the key for securing the rapidly evolving Internet-of-Things (IoT), where data security and privacy will become increasingly important in the forthcoming era. This research presents an innovative method for improving IDS performance through the integration of Artificial Intelligence (AI), Blockchain, and Digital Twin (DT) technologies. AI is utilized for real-time anomaly detection, whereas DT replicate device behavior for predicting threats and Blockchain ensures secure, decentralized data transmission. Energy-efficient zero-knowledge proofs are employed to meet the energy requirements of Blockchain, enhancing both security and resource efficiency. The performance of the suggested system will be assessed based on detection accuracy, latency, scalability, energy efficiency, and privacy preservation. This distinctive integration of advanced technologies delivers a multi-faceted security system, providing a thorough respond to for strengthening security in IoT networks.
Oqeili Saleh, Abu-alzanat Thamer, Alkaraimah Qutaibah, al smadi Takialddin
CAPTCHA, which stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart, is a commonly employed security measure to distinguish between humans and computers. The Turing Test, designed to guarantee network security, is the foundation of this security technique. Usability is a crucial concern that can prevent human users from engaging in laborious and time-consuming tasks. When designing CAPTCHA, security and usability must be addressed simultaneously. When designing CAPTCHA, it is crucial to address security and usability simultaneously. A concerted effort is required to protect online data and guarantee privacy and security. The personal information of Internet users remains susceptible to theft. This study uses an information extraction technique called CAPTCHA to investigate the hazards associated with violating user privacy. It is a highly harmful process due to hacking, theft, unauthorized reuse, and the breach of user information. This study proposes a privacy preservation system employing concurrent encryption techniques, multilateral security computing, and zero-knowledge proof. The objective is to create a system that allows for uncomplicated and secure puzzle-solving using dice gas. CAPTCHA limits access to users' information. In the overview and application of evidentiary measurable methods, we can draw significant conclusions about the more extensive client group's discernments and encounters with CAPTCHA as a privacy-preserving component.
The accelerating convergence of Cloud computing and the Internet of Things (IoT) has revolutionized data-driven services, yet it has also introduced a significant trust deficit in highly regulated sectors such as healthcare and finance. Traditional architectures, characterized by static security protocols and reactive monitoring, are increasingly inadequate for protecting sensitive medical records and financial assets against sophisticated cyber-threats and operational anomalies. This review article proposes a "Cognitive Cloud–IoT Architecture" that integrates human-like reasoning, self-learning, and context-aware decision-making into the data exchange process. We evaluate a multi-layered framework comprising an intelligent perception layer, a cognitive middleware reasoning engine, and a secure cloud core designed to establish objective trust through continuous verification. The study analyzes key mechanisms for trustworthy exchange, including Zero-Knowledge Proofs (ZKP), blockchain-enabled immutable ledgers, and privacy-preserving federated learning. In the healthcare domain, we examine the application of "cognitive patients" through remote monitoring systems that differentiate between sensor noise and clinical emergencies. In the financial sector, we explore the "cognitive ledger" for autonomous fraud forensics and secure cross-border settlements. Furthermore, the article addresses critical strategic challenges, such as the computational overhead of running cognitive models on edge devices and the legal necessity of algorithmic explainability. By synthesizing future trends, including quantum-safe hybridization and sovereign cognitive clouds, this research provides a comprehensive roadmap for developing resilient, intelligent ecosystems. Ultimately, we demonstrate that cognitive architecture is the essential bridge to an "invisible intelligence" that ensures the integrity of human life and global financial stability in an increasingly connected world.
Currently, privacy protection in consortium blockchains can be categorized into two primary schemes based on their characteristics. The first is the ring signature scheme, which renders the user identity completely anonymous. The second is the group signature scheme, where the user identity can be fully traced by the trusted authority (OA) in the event of a transaction dispute. To address the imbalance between privacy and accountability in consortium blockchain transactions, this paper introduces an enhanced multi-Key Generation Center (multi-KGC) group signature scheme tailored for consortium chains. We validate the anonymity and unforgeability of the proposed scheme through a security game. The enhanced group signature algorithm employs the Groth-Sahai proof system for non-interactive zero-knowledge proofs (NIZK) and leverages elliptic curve cryptography combined with threshold cryptography for key generation. This scheme is implemented within the Hyperledger Fabric consortium chain environment, and both computational and communication overheads are thoroughly analyzed. Experimental results indicate that, while the signature generation efficiency of the proposed scheme is slightly reduced compared to existing group signature schemes, its verification efficiency aligns with similar schemes. Functionally, our scheme facilitates a tiered disclosure of signing user information based on transaction values during transaction audits in consortium blockchain transactions.
Jin Qian, Jun Luo, Liquan Chen, Bangwei Yin · 6 authors
The authentication of identities within the smart grid system is crucial for ensuring its security and stable operation. With the emergence of smart grid technology, the significance of identity authentication in smart grid systems has become increasingly evident. Traditional authentication techniques, such as Direct Anonymous Attestation (DAA) based on RSA or ECC algorithm, face threats from quantum computing. On the other hand, lattice-based cryptography utilizes lattice structures and difficult problems to ensure the security and reliability of authentication against quantum computing threats, leading to the development of various Lattice-based Direct Anonymous Attestation (LDAA) protocols. In traditional LDAA schemes, the signature process involves using issued identity certificates to ensure trustworthiness. To maintain identity anonymity and trust, this process usually requires an additional commitment scheme and the use of large coefficient expressions for zero-knowledge proofs. This paper presents a single-domain LDAA scheme based on lattice cryptography. It significantly enhances authentication efficiency and performance by employing an innovative multiplication relations proof mechanism in lattices. Comparative experimental results validate the superiority of the proposed scheme.
Cai, Dongliang, Borui Chen, Liang Zhang, Haibin Kan
Attribute-based encryption (ABE) is a generalization of public-key encryption that enables fine-grained access control in cloud services. Recently, Hohenberger et al. (Eurocrypt 2023) introduced the notion of registered ABE, which is an ABE scheme without a trusted central authority. Instead, users generate their own public/secret keys and then register their keys and attributes with a key curator. The key curator is a transparent and untrusted entity and its behavior needs to be audited for malicious registration. In addition, pairing-based registered ABE still suffers the heavy decryption overhead like ABE. A general approach to address this issue is to outsource decryption to a decryption cloud service (DCS).In this work, we propose BA-ORABE, the first fully auditable registered ABE with reliable outsourced decryption scheme based on blockchain. First, we utilize a verifiable tag mechanism to achieve verifiability of ciphertext transformation, and the exemptibility which enables the honest DCS to escape from wrong claims is guaranteed by zero knowledge fraud proof under optimistic assumption. Additionally, our system achieves fairness and decentralized outsourcing to protect the interests of all parties and the registration and outsourcing process are transparent and fully auditable through blockchain. Finally, we give security analysis, implement and evaluate our scheme on Ethereum to demonstrate its feasibility and efficiency, and show its advantages in real application of decentralized finance.
AegisLibre is a novel decentralized storage algorithm designed to prioritize high security and efficiency for sensitive data like personal information, text, photos, and other private content. Drawing inspiration from blockchain technology, it combines dynamic encryption, smart contracts, zero-knowledge proofs (ZKP), and Proof of Storage (PoS) to offer a highly secure and verifiable storage system. This paper explores the foundations of AegisLibre, compares it with existing algorithms such as IPFS, discusses its key features, and presents an analysis of its security capabilities and performance.
Existing federated learning (FL) systems are highly vulnerable in terms of security and privacy due to their distributed architecture, facing poisoning attacks and inference attacks from adversaries. Some prior works have combined poisoning defenses with cryptographic tools: Secure Multi-Party Computation, Zero-Knowledge Proof, and Homomorphic Encryption to propose robust secure aggregation methods that provide security and privacy preservation for FL. Recently, Qin et al. (KDD’23) demonstrate that personalized federated learning (pFL) can effectively resist backdoor injection in poisoning attacks. In this paper, we analyze that as the number of malicious attackers increases, pFL remains vulnerable to backdoor attacks. Moreover, we reveal that current robust secure aggregation methods fail to offer efficient and robust backdoor defense for pFL. Therefore, we propose FLIGHT, a robust secure aggregation method for pFL. It implements a lightweight backdoor detection through a two-stage personalized defense mechanism and ensures privacy preservation using communication-efficient two-party secure computation (2PC) protocols. Extensive experiments on diverse datasets and neural networks validate that FLIGHT decreases run-time up to 64× compared by prior work RoFL (S&P’23), and 42× compared to FLAME (USENIX Security’22).
5G networks provide secure and reliable information transmission services for the Internet of Everything, thus paving the way for 6G networks, which is anticipated to be an AI-based network, supporting unprecedented intelligence across applications. Abundant computing resources will establish the 6G Computing Power Network (CPN) to facilitate ubiquitous intelligent services. In this article, we propose BECS, a computing sharing mechanism based on evolutionary algorithm and blockchain, designed to balance task offloading among user devices, edge devices, and cloud resources within 6G CPN, thereby enhancing the computing resource utilization. We model computing sharing as a multi-objective optimization problem, aiming to improve resource utilization while balancing other issues. To tackle this NP-hard problem, we devise a kernel distance-based dominance relation and incorporated it into the Non-dominated Sorting Genetic Algorithm III, significantly enhancing the diversity of the evolutionary population. In addition, we propose a pseudonym scheme based on zero-knowledge proof to protect the privacy of users participating in computing sharing. Finally, the security analysis and simulation results demonstrate that BECS can fully and effectively utilize all computing resources in 6G CPN, significantly improving the computing resource utilization while protecting user privacy.
Zero-knowledge proof (ZKP) is an attractive cryptographic paradigm that allows a party to prove the correctness of a given statement without revealing any additional information. It offers both computation integrity and privacy, witnessing many celebrated deployments, such as computation outsourcing and cryptocurrencies. Recent general-purpose ZKP schemes, e.g., zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK), suffer from time-consuming proof generation, which is mainly bottlenecked by the large-scale number theoretic transformation (NTT) and multi-scalar point multiplication (MSM). To boost its wide application, great interest has been shown in expediting the proof generation on various platforms like GPU, FPGA and ASIC.So far as we know, current works on the hardware designs for ZKP employ two separated data-paths for NTT and MSM, overlooking the potential of resource reusage. In this work, we particularly explore the feasibility and profit of implementing both NTT and MSM with a unified and high-performance hardware architecture. For the crucial operator design, we propose a dual-precision, load-balanced and fully-pipelined Montgomery multiplier (LBFP MM) by introducing the new mixed-radix technique and improving the prior quotient-decoupled strategy. Collectively, we also integrate orthogonal ideas to further enhance the performance of LBFP MM, including the customized constant multiplication, truncated LSB/MSB multiplication/addition and Karatsuba technique. On top of that, we present the unified, scalable and highperformance hardware architecture that conducts both NTT and MSM in a versatile pipelined execution mechanism, intensively sharing the common computation and memory resource. The proposed accelerator manages to overlap the on-chip memory computation with off-chip memory access, considerably reducing the overall cycle counts for NTT and MSM.We showcase the implementation of modular multiplier and overall architecture on the BLS12-381 elliptic curve for zk-SNARK. Extensive experiments are carried out under TSMC 28nm synthesis and similar simulation set, which demonstrate impressive improvements: (1) the proposed LBFP MM obtains 1.8x speed-up and 1.3x less area cost versus the state-of-the-art design; (2) the unified accelerator achieves 12.1x and 5.8x acceleration for NTT and MSM while also consumes 4.3x lower overall on-chip area overhead, when compared to the most related and advanced work PipeZK.
Osama Elghazaly, Nidal Nasser, Ahmed El Ouadrhiri, Asmaa Ali
Blockchain-based smart contracts, while transformative, pose privacy concerns due to Ethereum's transparency. To address this, we present Safe Smart Contracts (SafeSC), leveraging zk-SNARKs for privacy without compromising Ethereum's transparency. SafeSC's Python tool facilitates contract understanding and verification without accessing the source code. Our paper explores privacy preservation techniques, favoring Zero-Knowledge Proofs (ZKPs). SafeSC employs zk-SNARKs and Groth-16, achieving a delicate balance between transparency and privacy in smart contract development. The tool’s design, covering architecture, assumptions, data flow, and zero-knowledge proof workflow, marks a step toward secure smart contract solutions. We advocate for continued exploration and refinement to enhance blockchain technologies.